-
Notifications
You must be signed in to change notification settings - Fork 227
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Stackoverflow CVE-2022-40151 #314
Comments
There seems to be some recursion possible in
Snippet of the stacktrace of using the crashing input:
|
@henryrneh: Thanks for providing the test case here, you did not attach it sending the private mail to me. |
another vulnerability also reported: https://nvd.nist.gov/vuln/detail/CVE-2022-40152 |
This report is simply rubbish! #304 |
CVE-2022-40152 is not directly related to stream: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40152. |
Thanks for the link, now I get the full picture. @joehni @cesarhernandezgt |
Dear xstream maintainers and users,
the following zip contains crashing input, stacktrace, the fuzz target and all the information needed to reproduce CVE-2022-40151.
Please have a look and contact us if you need more information, thanks.
47367.zip
The text was updated successfully, but these errors were encountered: